All Resources
News·5 Mar 2026·5 min read

Canada's Bill C-8 Will Force Mandatory Cybersecurity on Critical Sectors

Canada's Bill C-8, An Act respecting cyber security which amends the Telecommunications Act, establishes the Critical Cyber Systems Protection Act - introducing mandatory cybersecurity requirements for organisations operating critical infrastructure, in sectors that have historically had far lighter statutory obligations than their US or UK counterparts. Separately, a new federal private-sector privacy statute is expected in 2026, intended to replace key elements of PIPEDA, the framework that has governed private-sector data handling in Canada since 2000.

Canada's current patchwork

Unlike the UK or the EU, Canada doesn't have a single, unified cybersecurity law today - businesses navigate a combination of federal privacy legislation (PIPEDA), anti-spam rules, provincial privacy statutes, and sector-specific regulation. Quebec's Law 25 is currently the most stringent private-sector privacy law in the country, with higher penalties, mandatory privacy officer roles, and tighter controls on automated decision-making than the federal baseline. PIPEDA itself already requires mandatory breach reporting for any breach creating a "real risk of significant harm," with fines up to CAD $100,000 per violation for non-compliance.

What this means for firms operating in Canada

  • If your organisation, or a key vendor, touches critical infrastructure sectors, Bill C-8 signals that Canada is moving toward the same statutory-obligation model the UK and EU have already adopted - plan for mandatory requirements rather than voluntary best practice.
  • Quebec's Law 25 is a useful preview of where the coming federal privacy overhaul may head - treating it as the compliance ceiling rather than a provincial exception is a reasonable planning assumption.
  • The current patchwork won't last much longer; organisations operating across multiple provinces should expect consolidation toward a stricter, more unified federal standard rather than continued fragmentation.

Have a security question of your own?

Talk to a Security Expert →